Scratching the Surface of Rhysida Ransomware
ID: c094d726-511b-5a9c-a19f-1c6ba7b49b6b
STIX ID: report--c094d726-511b-5a9c-a19f-1c6ba7b49b6b
Feed Name: WatchGuard Secplicity Blog
This report analyzes an early-stage Rhysida ransomware sample: unpacked MinGW-built binary (~1.2MB) that uses ChaCha20 for file encryption with AES/CHC constructs and RSA-4096-OAEP to encrypt keys, appends the .rhysida extension, drops a PDF ransom note (CriticalBreachDetected.pdf) and exposes a TOR extortion portal (no victims observed). It documents command-line options, self-deletion via PowerShell, files/directories excluded from encryption, and provides file hashes and behavioral details useful for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
